PT-2023-1665 · Microsoft · Windows Server 2022+7

Erik Egsgard

·

Published

2023-03-14

·

Updated

2024-11-11

·

CVE-2023-23415

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Windows Server 2008 versions prior to Mar 14, 2023 Windows Server 2012 versions prior to Mar 14, 2023 Windows Server 2016 versions prior to Mar 14, 2023 Windows 10 versions prior to Mar 14, 2023 Windows 11 versions prior to Mar 14, 2023 Windows Server 2022 versions prior to Mar 14, 2023 Windows Server 2019 versions prior to Mar 14, 2023
Description The vulnerability is related to the implementation of the Internet Control Message Protocol (ICMP) in the Windows operating system kernel, which is associated with insufficient input validation. This issue can be exploited by a remote attacker to execute arbitrary code. The exploitation involves a low-level protocol error containing a fragmented IP packet in the header sent to the target machine.
Recommendations For Windows Server 2008, update to a version released after Mar 14, 2023. For Windows Server 2012, update to a version released after Mar 14, 2023. For Windows Server 2016, update to a version released after Mar 14, 2023. For Windows 10, update to a version released after Mar 14, 2023. For Windows 11, update to a version released after Mar 14, 2023. For Windows Server 2022, update to a version released after Mar 14, 2023. For Windows Server 2019, update to a version released after Mar 14, 2023.

Exploit

Fix

RCE

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-01227
CVE-2023-23415

Affected Products

Windows
Windows 10
Windows 11
Windows Server 2008
Windows Server 2012
Windows Server 2016
Windows Server 2019
Windows Server 2022